CVE-2020-17353
05.08.2020, 14:15
scm/define-stencil-commands.scm in LilyPond through 2.20.0, and 2.21.x through 2.21.4, when -dsafe is used, lacks restrictions on embedded-ps and embedded-svg, as demonstrated by including dangerous PostScript code.Enginsight
| Vendor | Product | Version |
|---|---|---|
| lilypond | lilypond | 𝑥 ≤ 2.20.0 |
| lilypond | lilypond | 2.21.0 ≤ 𝑥 ≤ 2.21.4 |
| debian | debian_linux | 10.0 |
| opensuse | backports_sle | 15.0:sp2 |
| opensuse | leap | 15.2 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
References